Fallos del tipo CWE-312

470 resultados

Divulgação de Informações Sensíveis

É quando a aplicação expõe dados sensíveis (senhas, tokens, dados pessoais, chaves de API) de forma não intencional — seja em logs, respostas de erro, memória, ou tráfego de rede. O risco é que um atacante, desenvolvedor mal-intencionado ou até um usuário comum consegue acessar informações que deveriam estar protegidas.

Ejemplo

Uma API retorna a senha do usuário em texto plano na resposta JSON de erro; um servidor deixa stack traces detalhados visíveis em páginas de erro 500, revelando caminhos internos e bibliotecas usadas; ou um formulário de login inclui o token de sessão como parâmetro GET em logs de proxy.

Cómo mitigar

Nunca logarque dados sensíveis; sanitize mensagens de erro para o cliente (mostre apenas identificadores genéricos); use variáveis de ambiente para secrets e nunca as commite; implemente logs estruturados apenas no servidor, sem expô-los. Revise regularmente o que sua app entrega em respostas, headers e logs.

CVE-2023-28713HIGHPlaintext storage of a password exists in CONPROSYS HMI System (CHS) versions prior to 3.5.3. Because account information of the database isEPSS 0.4%CVE-2022-2813MEDIUMSourceCodester Guest Management System cleartext storageEPSS 0.4%CVE-2022-2805MEDIUMA flaw was found in ovirt-engine, which leads to the logging of plaintext passwords in the log file when using otapi-style. This flaw allowsEPSS 0.4%CVE-2023-31408MEDIUMCleartext Storage of Sensitive Information in SICK FTMg AIR FLOW SENSOR with Partnumbers 1100214, 1100215, 1100216, 1120114, 1120116, 112252EPSS 0.4%CVE-2024-32474HIGHSentry's superuser cleartext password leaked in logsEPSS 0.4%CVE-2022-34339MEDIUM"IBM Cognos Analytics 11.2.1, 11.2.0, 11.1.7 stores user credentials in plain clear text which can be read by an authenticated user. IBM X-FEPSS 0.4%CVE-2023-44159MEDIUMSensitive information disclosure due to cleartext storage of sensitive information. The following products are affected: Acronis Cyber ProteEPSS 0.4%CVE-2020-36887HIGHSpinetiX Fusion Digital Signage 3.4.8 Unauthenticated Database Backup DisclosureEPSS 0.4%CVE-2023-22949MEDIUMAn issue was discovered in TigerGraph Enterprise Free Edition 3.x. There is logging of user credentials. All authenticated GSQL access requeEPSS 0.4%CVE-2021-42066—SAP Business One - version 10.0, allows an admin user to view DB password in plain text over the network, which should otherwise be encrypteEPSS 0.4%CVE-2023-50957HIGHIBM Storage Defender - Resiliency Service privilege escalationEPSS 0.4%CVE-2022-38112HIGHSensitive Information Disclosure VulnerabilityEPSS 0.4%CVE-2020-6980—Rockwell Automation MicroLogix 1400 Controllers Series B v21.001 and prior, Series A, all versions, MicroLogix 1100 Controller, all versionsEPSS 0.4%CVE-2023-48700MEDIUMClear Text Credentials Exposed via Onboarding TaskEPSS 0.4%CVE-2023-29480HIGHRibose RNP before 0.16.3 sometimes lets secret keys remain unlocked after use.EPSS 0.4%CVE-2021-22929—An information disclosure exists in Brave Browser Desktop prior to version 1.28.62, where logged warning messages that included timestamps oEPSS 0.4%CVE-2023-2809HIGHUse of Cleartext credentials in Sage 200 SpainEPSS 0.4%CVE-2023-30528MEDIUMJenkins WSO2 Oauth Plugin 1.0 and earlier does not mask the WSO2 Oauth client secret on the global configuration form, increasing the potentEPSS 0.4%CVE-2023-30531MEDIUMJenkins Consul KV Builder Plugin 2.0.13 and earlier does not mask the HashiCorp Consul ACL Token on the global configuration form, increasinEPSS 0.4%CVE-2024-22084HIGHAn issue was discovered in Elspec G5 digital fault recorder versions 1.1.4.15 and before. Cleartext passwords and hashes are exposed throughEPSS 0.4%